STIGQter STIGQter: STIG Summary: Oracle Database 11g Installation STIG Version: 8 Release: 20 Benchmark Date: 28 Jul 2017:

Database software, applications and configuration files should be monitored to discover unauthorized changes.

DISA Rule

SV-24383r1_rule

Vulnerability Number

V-2423

Group Title

DBMS software and configuration file monitoring

Rule Version

DG0050-ORACLE11

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Develop, document and implement procedures to monitor for unauthorized changes to DBMS software libraries, related software application libraries and configuration files.

If a third-party automated tool is not employed, an automated job that reports file information on the directories and files of interest and compares them to the baseline report for the same will meet the requirement.

File hashes or checksums should be used for comparisons as file dates may be manipulated by malicious users.

Check Contents

Review documented software and configuration monitoring procedures and implementation evidence to verify that monitoring of changes to database software libraries, related applications and configuration files is being performed weekly or more often.

Verify that a list of files and directories being monitored is complete.

If monitoring is not being performed weekly or more often, this is a Finding.

If implementation evidence is not complete, this is a Finding.

Vulnerability Number

V-2423

Documentable

False

Rule Version

DG0050-ORACLE11

Severity Override Guidance

Review documented software and configuration monitoring procedures and implementation evidence to verify that monitoring of changes to database software libraries, related applications and configuration files is being performed weekly or more often.

Verify that a list of files and directories being monitored is complete.

If monitoring is not being performed weekly or more often, this is a Finding.

If implementation evidence is not complete, this is a Finding.

Check Content Reference

I

Responsibility

Database Administrator

Target Key

1368

Comments